Operation DragonReturn DcRAT AV Enumeration via GetSystemInfo Reporting to C2
Detects svchost.exe or 'Mixed Reality.exe' spawning common system and security enumeration tools (such as wmic.exe, systeminfo.exe, or tasklist.exe) with command-line arguments indicative of the DcRAT 'SendInfo()' routine. This pattern is characteristic of malware performing reconnaissance of installed security software and system identification.
Cortex XDR

